3GPP 5G Security Architecture (TS 33.501)
Service Based Architecture Security

3GPP 5G Security Architecture (TS 33.501) TS33.501-13.4: OAuth 2.0 Authorization Framework

NF service consumer authorization using OAuth 2.0 tokens issued by NRF

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 54 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management

SOC 2 · 2 controls

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27043:2015 · 1 control

  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-14 Privileged access management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-190 · 1 control

  • NIST190-08 Privileged access in cloud environments
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain

South Korea ISMS-P · 1 control

  • ISMSP-AC-01 Access Control Policy
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • UGA-10 Sensitive Personal Data Prohibition

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Service Based Architecture Security

Query this from an agent

The graph holds this control, the 54 it maps to, and the evidence behind each claim, over MCP and REST.